Skip to main content

Vendor archive

arista CVEs

Beta · best-effort

100 CVEs tagged to vendor arista15 Critical, 40 High, 38 Medium, 7 Low, 0 Unrated.

CVE-2026-16812

Published Jul 27, 2026

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Success…

CVSS 10.0 · Critical
evidence mentions
7
Buzz score
65.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-25624

Published Jun 5, 2026

An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NG…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25623

Published Jun 5, 2026

An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authentica…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25622

Published Jun 5, 2026

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an adminis…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25621

Published Jun 5, 2026

A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue un…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25620

Published Jun 5, 2026

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW).…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2767

Published Apr 23, 2025

Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-9188

Published Jan 10, 2025

Specially constructed queries cause cross platform scripting leaking administrator tokens

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9134

Published Jan 10, 2025

Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to e…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47520

Published Jan 10, 2025

A user with advanced report application access rights can perform actions for which they are not authorized

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47518

Published Jan 10, 2025

Specially constructed queries targeting ETM could discover active remote access sessions

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47517

Published Jan 10, 2025

Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12832

Published Dec 20, 2024

Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files and disclose sensiti…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12831

Published Dec 20, 2024

Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12830

Published Dec 20, 2024

Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12829

Published Dec 20, 2024

Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27889

Published Mar 4, 2024

Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 100 CVEsPage 1 of 4